I removed viruses from laptop .Now at startup i get mesage "windows cannot open C:\windows\sembako-cgzjplg.exe "
It's a spyware file . How do i get windows to stop searching for it at startup?
- Follow via:
- RSS
- Email Alert
Question
0
Votes
Answers (5)
0
Votes
Read this: ...
http://www.bleepingcomputer.com/startups/sembako_cfzjkmg.exe-13961.html
You could try booting into Safe Mode with Networking, then running the online scan from there.
Alternately you could remove the hard drive, place it in a caddy, then scan it as a slave from another (uninfected) computer.
You could try booting into Safe Mode with Networking, then running the online scan from there.
Alternately you could remove the hard drive, place it in a caddy, then scan it as a slave from another (uninfected) computer.
20th Feb 2009
0
Votes
msconfig
try start>run>msconfig
click the startup tab (and maybe services)
see if you can find something that looks like *sembako*
uncheck the box
restart and scan again
if that doesnt work you should try hijackthis
good luck and post back!
click the startup tab (and maybe services)
see if you can find something that looks like *sembako*
uncheck the box
restart and scan again
if that doesnt work you should try hijackthis
good luck and post back!
20th Feb 2009
0
Votes
Removal
For basic spyware removal, i use Spybot S&D from download.com. It's a free program, but its good at what it does. However, it sounds like the file was already removed.
20th Feb 2009
0
Votes
spyware
Chances are you may have a .dll hidden somewhere that attempting to open the file on startup.
I would try the following.
Run Spybot Search and Destroy to see if you can find the location of any spyware. Write down the locations of the files. Disable system restore and reboot in safemode. Run Spybot again then reboot normally.
The reason disabling system restore is important is because the PC may have created a restore point during the time that file was on your PC essentially putting it back on the PC evertime it loads. After you've determined the spyware was deleted simply re-enable system restore and create a new restore point.
Hope this helps.
I would try the following.
Run Spybot Search and Destroy to see if you can find the location of any spyware. Write down the locations of the files. Disable system restore and reboot in safemode. Run Spybot again then reboot normally.
The reason disabling system restore is important is because the PC may have created a restore point during the time that file was on your PC essentially putting it back on the PC evertime it loads. After you've determined the spyware was deleted simply re-enable system restore and create a new restore point.
Hope this helps.
20th Feb 2009
Replies
I have done as you said but it ditnot work. I looked in msconfig for file but nothing.i am still geting the mesage ,.Windows cannot find "C:\WINDOWS\sembako-cgzjlpg.exe".
christjan@...
23rd Feb 2009
0
Votes
Follow this link
and if it isn't already on More Information click it. It will give you access to Registry keys to enable you to find it. But first you may need to do this if you can't access the Registry.
Click Start Run and type cmd and then press Enter.
Execute the following commands in the command line in order to activate the registry editor and Task Manager: answer -? y ? - and press Enter.
reg delete HKCU\Software\Microsoft\Windows\CurrentVersion\Policies\System /v DisableTaskMgr
reg delete HKCU\Software\Microsoft\Windows\CurrentVersion\Policies\System /v DisableRegistryTools
http://www.sophos.com/security/analyses/viruses-and-spyware/w32brontokm.html
Edit: formatting
♪♫
Click Start Run and type cmd and then press Enter.
Execute the following commands in the command line in order to activate the registry editor and Task Manager: answer -? y ? - and press Enter.
reg delete HKCU\Software\Microsoft\Windows\CurrentVersion\Policies\System /v DisableTaskMgr
reg delete HKCU\Software\Microsoft\Windows\CurrentVersion\Policies\System /v DisableRegistryTools
http://www.sophos.com/security/analyses/viruses-and-spyware/w32brontokm.html
Edit: formatting
♪♫
Updated - 23rd Feb 2009
Replies
That worked used regedit and found it in windows\sistem.sys and deleted it . that link helped a lot to pinpoint it. thanks a lot.
christjan@...
24th Feb 2009
good to see that you are up and running.
Jacky Howe
24th Feb 2009

































